Security-X

Forum Security-X => Désinfections => Discussion démarrée par: thanelia93 le octobre 22, 2012, 21:46:32

Titre: PC Espionné ?
Posté par: thanelia93 le octobre 22, 2012, 21:46:32
Voilà j'ai une autre demande un peu plus délicate.
Je soupçonne mon ex mari de voir mon activité sur un autre ordinateur chez moi qui aurait besoin également d'être "nettoyé".
Mais comment savoir et comment le prouver ?
J'en ai l'intime conviction mais pas la preuve.
Merci encore pour tous les précieux conseils qui m'ont permis de désinfecter l'autre ordinateur.
 :AAF
Titre: Re : PC Espionné ?
Posté par: hyunkel30 le octobre 22, 2012, 22:27:58
Bonsoir,

Ce serait quel genre "d'espionnage" ?
Parce que si c'est mail ou autre, ce n'est pas obligatoirement sur le pc, mais les mot de passe qu'il faut modifier ...
Titre: Re : PC Espionné ?
Posté par: thanelia93 le octobre 25, 2012, 09:31:13
Etant donné que nous avons vécu ensemble, peut il avoir installé sur mon PC un logiciel qui lui permette de voir mon écran ?
Et qui lui permet encore maintenant de voir mon activité.
Mon PC est lent mais il y a eu une période où il était en vacances loin où mon PC comme par hasard était en mode turbo.
En deux ans, je n'avais jamais vu cela.
Mais comment le savoir ?
Titre: Re : PC Espionné ?
Posté par: hyunkel30 le octobre 25, 2012, 10:49:09
Re,

Non, quand je demandais "quel genre", je voulais dire, as-tu eu des "preuves" d'un espionnage ?
T'a-t-il montré quelque chose qu'il ne devrait pas avoir vu ? (copie de mail, capture d'écran, etc ...)
Cela orienterait déjà les recherches ...

Citer
Mon PC est lent mais il y a eu une période où il était en vacances loin où mon PC comme par hasard était en mode turbo.
Mouais, généralement les spywares sont fait pour rester inaperçu, donc ... pas vraiment un indice ;)


On peut toujours jeter un oeil, mais généralement dans ce genre d'impression, il y a le plus souvent une part de paranoïa, sans vouloir être blessant. Je vais te dire qu'il n'y a rien, et tu ne sera pas satisfaite, ou je vais te dire "peut-être que ..." et tu broderas.
Donc pour le moment restons zen, et pas de conclusion rapide.

à faire :

Télécharge OTL (http://oldtimer.geekstogo.com/OTL.exe) (de Old Timer) sur ton bureau.


netsvcs
msconfig
drivers32
activex
/md5start
explorer.exe
wininit.exe
winlogon.exe
userinit.exe
kernel32.dll
services.exe
/md5stop
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\syswow64\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\syswow64\drivers\*.sys /lockedfiles
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
CREATERESTOREPOINT


Une aide à l'utilisation ici (http://forum.security-x.fr/cours-et-tutoriels-322/(tutoriel)-impression-d%27ecran-et-hebergement-de-rapport/msg60884/#msg60884)

Note : Les rapports sont aussi enregistrés sur le bureau
Titre: Re : PC Espionné ?
Posté par: thanelia93 le octobre 25, 2012, 11:43:11
Je fais cela ... :) Merci
Disons que ma messagerie avait déjà été piratée par deux fois.
Que des captures d'écran apparaissant dans des procédures juridiques m'ont titillé.
Ainsi qu'une information qu'il a pris connaissance je ne sais comment.
Je préfère en avoir le coeur net et s'il n'y a rien, je vais me faire une raison.
Mais c'est mieux de vérifier.
Et je reste Zen ... Ne t'inquiète pas pour le propos, cela ne me blesse pas.
J'aime la franchise des mots.
Titre: Re : PC Espionné ?
Posté par: thanelia93 le octobre 25, 2012, 11:45:52
Et je sais qu'il y a des programmes qui existent où tu peux prendre la main sur l'ordi sans que la personne ne s'en rende compte.
En plus, je n'éteins pas souvent mon ordinateur.
Bon ok je me tais je vais faire la procédure et je poste tout cela.
Merci
Titre: Re : PC Espionné ?
Posté par: thanelia93 le octobre 25, 2012, 12:33:03
http://security-x.fr/up/file.php?h=R972f7933021195335f62ee9ace42a515
http://security-x.fr/up/file.php?h=R8914e28de6e5316fa2e69d47451d4187

Et voilà .... il y aussi du menage à faire sur celui ci
Titre: Re : PC Espionné ?
Posté par: hyunkel30 le octobre 25, 2012, 14:22:32
Re,

Bon, dans l'ordre :

Citer
Drive C: | 74,53 Gb Total Space | 2,68 Gb Free Space | 3,60% Space Free | Partition Type: NTFS

Ton disque dur est saturé, provoquant ralentissement et baisse de performance, tu dois absolument supprimé tout programme inutile, et archiver sur d'autres supports tes données personnelles (documents, photos, vidéos, etc ...)

Ensuite :

Tu possèdes deux antivirus actifs :
- Microsoft Security Essentials
- Kaspersky 2011

Multiplier les protections n'améliore pas la sécurité, et peut provoquer ralentissements et conflits
Supprime l'un des deux antivirus.


Puis, niveau ménage : (Pour info, rien qui soit lié à un quelconque spyware, juste des adwares, logiciels publicitaires)

1) Désinstalle les programmes suivants dans ta liste des programmes (si présents) :

Note : Si tu rencontres une erreur passe au suivant et poursuis la procédure

- Orange Plug-in messagerie vocale 888 (sauf réelle utilité)
- J2SE Runtime Environment 5.0 Update 6
- Java(TM) SE Runtime Environment 6 Update 1 (versions obsolètes et vulnérable)
- BS.Player ControlBar (sauf réelle utilité)
- Yahoo! BrowserPlus 2.9.8 (idem)
- Serials 2000 7.1+ (l'utilisation de serial est illégal, et potentiellement dangereux)

- Search Settings 1.2 (adware : logiciel publicitaire)
- Freecorder Toolbar et Freecorder Toolbar 3.0 Application (barre d'outil sponsorisée par un adware)
- Vuze Remote Toolbar (idem)


2) Télécharge AdwCleaner (http://general-changelog-team.fr/fr/downloads/viewdownload/20-outils-de-xplode/2-adwcleaner) (de Xplode) sur ton Bureau.




3)) Relance  OTL.exe


/!\ Attention, utilisateur d'Avast! ou d'autres antivirus, ne lancez pas OTL en mode sandbox /!\



:OTL
DRV - [2011/02/10 08:38:58 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\uti3otqy.sys -- (uti3otqy)
IE - HKU\S-1-5-21-2711178871-2754835319-3042192345-1005\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://y.lo.st
IE - HKU\S-1-5-21-2711178871-2754835319-3042192345-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://y.lo.st
IE - HKU\S-1-5-21-2711178871-2754835319-3042192345-1005\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.5.0.12
FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=SP_ss&mntrId=9ca401050000000000000016e39af381&tlver=1.4.19.19&instlRef=sst&ss=1&affID=18026&q="
[2010/10/22 01:45:14 | 000,000,000 | ---D | M] (Freecorder Toolbar) -- C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2011/06/29 16:56:33 | 000,000,000 | ---D | M] (Vuze Remote Community Toolbar) -- C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2010/10/22 01:45:37 | 000,000,000 | ---D | M] (Torrent Finder Toolbar) -- C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder
[2011/02/09 14:54:24 | 000,002,395 | ---- | M] () -- C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\searchplugins\askcom.xml
[2008/10/22 21:25:24 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\searchplugins\bsplayer-search.xml
[2011/08/10 20:28:32 | 000,002,441 | ---- | M] () -- C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\searchplugins\dealio.xml
[2008/06/11 23:49:51 | 000,000,000 | ---D | M] (Search Settings Plugin) -- C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
[2008/05/31 18:29:08 | 000,024,683 | ---- | M] (Ask.com) -- C:\Program Files\mozilla firefox\plugins\NPAskSBr.dll
O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll (Conduit Ltd.)
O2 - BHO: (no name) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - No CLSID value found.
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O2 - BHO: (SearchSettings Class) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll (Vendio Services, Inc.)
O2 - BHO: (no name) - {E33CF602-D945-461A-83F0-819F76A199F8} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-2711178871-2754835319-3042192345-1005\..\Toolbar\ShellBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Program Files\Freecorder\tbFre0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-2711178871-2754835319-3042192345-1005\..\Toolbar\WebBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Program Files\Freecorder\tbFre0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-2711178871-2754835319-3042192345-1005\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O15 - HKLM\..Trusted Domains: canalplay.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Domains: canalplusactive.com ([]* in Trusted sites)
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^RAMASST.lnk -  - File not found
MsConfig - StartUpReg: BlazeServoTool - hkey= - key= - Reg Error: Value error. File not found
MsConfig - StartUpReg: CanalPlayerHelper - hkey= - key= - Reg Error: Value error. File not found
MsConfig - StartUpReg: CFSServ.exe - hkey= - key= -  File not found
MsConfig - StartUpReg: EoEngine - hkey= - key= -  File not found
MsConfig - StartUpReg: eorezo - hkey= - key= - Reg Error: Value error. File not found
MsConfig - StartUpReg: Nqaqafari - hkey= - key= -  File not found
MsConfig - StartUpReg: SearchSettings - hkey= - key= - C:\Program Files\Search Settings\SearchSettings.exe (Vendio Services, Inc.)
MsConfig - StartUpReg: SoftwareHelper - hkey= - key= - Reg Error: Value error. File not found
MsConfig - StartUpReg: WhenUSave - hkey= - key= - Reg Error: Value error. File not found
MsConfig - StartUpReg: YeppStudioAgent - hkey= - key= - Reg Error: Value error. File not found
MsConfig - StartUpReg: Zooming - hkey= - key= -  File not found
[33 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2012/10/24 23:14:00 | 000,000,492 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/02/10 08:38:56 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\uti3otqy.sys
[2011/08/12 16:53:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
[2011/04/14 13:31:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2011/04/03 22:54:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/05/01 16:05:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2011/05/30 21:08:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\muchacha\Application Data\BabylonToolbar
[2008/06/13 07:58:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\muchacha\Application Data\Search Settings

:Files
C:\Program Files\Search Settings

:Commands
[emptytemp]
[resethosts]



Note : le rapport est enregistré sous format ".log", il convient de changer cette extension en ".txt" si tu veux le déposer sur des sites en ligne. S'il n'apparait pas, il se trouve ici : C:\_OTL, sous la forme xxxxxxxx_xxxx.log où x sont la date et l'heure

/!\ Ce script est exclusivement réservé à l'utilisateur actuel du sujet, vous ne devez en aucun cas l'utiliser de votre propre chef sur un autre pc, sous risque d'endommager le système /!\
Titre: Re : PC Espionné ?
Posté par: thanelia93 le octobre 25, 2012, 18:54:38
bon ben voilà

Par contre je n'arrive pas à enlever Kaspersky 2011

All processes killed
========== OTL ==========
Service uti3otqy stopped successfully!
Service uti3otqy deleted successfully!
C:\WINDOWS\system32\drivers\uti3otqy.sys moved successfully.
HKU\S-1-5-21-2711178871-2754835319-3042192345-1005\SOFTWARE\Microsoft\Internet Explorer\Main\\First Home Page| /E : value set successfully!
HKU\S-1-5-21-2711178871-2754835319-3042192345-1005\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-2711178871-2754835319-3042192345-1005\Software\Microsoft\Internet Explorer\URLSearchHooks\\{ba14329e-9550-4989-b3f2-9732e92d17cc} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
File C:\Program Files\Vuze_Remote\prxtbVuz0.dll not found.
Prefs.js: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.5.0.12 removed from extensions.enabledItems
Prefs.js: "http://search.babylon.com/?babsrc=SP_ss&mntrId=9ca401050000000000000016e39af381&tlver=1.4.19.19&instlRef=sst&ss=1&affID=18026&q=" removed from keyword.URL
Folder C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\ not found.
Folder C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\defaults\preferences folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\defaults folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\skin\logos folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\skin folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\zh-CN folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\vi-VN folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\tr-TR folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\sk-SK folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\ru-RU folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\pt-PT folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\pt-BR folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\pl-PL folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\nl-NL folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\it-IT folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\hu-HU folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\hr-HR folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\fr-FR folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\fi-FI folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\et-EE folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\es-ES folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\en-US folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\el-GR folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\de-DE folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale\ar folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\locale folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome\content folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder\chrome folder moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\extensions\TFToolbarX@torrent-finder folder moved successfully.
File C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\searchplugins\askcom.xml not found.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\searchplugins\bsplayer-search.xml moved successfully.
C:\Documents and Settings\muchacha\Application Data\Mozilla\Firefox\Profiles\fbbov2nr.default\searchplugins\dealio.xml moved successfully.
Folder C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\ not found.
File C:\Program Files\mozilla firefox\plugins\NPAskSBr.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\ not found.
File C:\Program Files\Freecorder\tbFre0.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
File C:\Program Files\Vuze_Remote\prxtbVuz0.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\ not found.
File C:\Program Files\Search Settings\kb127\SearchSettings.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E33CF602-D945-461A-83F0-819F76A199F8}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{1392b8d2-5c05-419f-a8f6-b9f15a596612} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\ not found.
File C:\Program Files\Freecorder\tbFre0.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ba14329e-9550-4989-b3f2-9732e92d17cc} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
File C:\Program Files\Vuze_Remote\prxtbVuz0.dll not found.
Registry value HKEY_USERS\S-1-5-21-2711178871-2754835319-3042192345-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{1392B8D2-5C05-419F-A8F6-B9F15A596612} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1392B8D2-5C05-419F-A8F6-B9F15A596612}\ not found.
File C:\Program Files\Freecorder\tbFre0.dll not found.
Registry value HKEY_USERS\S-1-5-21-2711178871-2754835319-3042192345-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1392B8D2-5C05-419F-A8F6-B9F15A596612} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1392B8D2-5C05-419F-A8F6-B9F15A596612}\ not found.
File C:\Program Files\Freecorder\tbFre0.dll not found.
Registry value HKEY_USERS\S-1-5-21-2711178871-2754835319-3042192345-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BA14329E-9550-4989-B3F2-9732E92D17CC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA14329E-9550-4989-B3F2-9732E92D17CC}\ not found.
File C:\Program Files\Vuze_Remote\prxtbVuz0.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\canalplay.com\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\canalplusactive.com\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^RAMASST.lnk\ deleted successfully.
File Reg Error: Value error. not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\BlazeServoTool\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\CanalPlayerHelper\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\CFSServ.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\EoEngine\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\eorezo\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\Nqaqafari\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SearchSettings\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SoftwareHelper\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\WhenUSave\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\YeppStudioAgent\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\Zooming\ deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\System32\SET11E.tmp deleted successfully.
C:\WINDOWS\System32\SET153.tmp deleted successfully.
C:\WINDOWS\System32\SET168.tmp deleted successfully.
C:\WINDOWS\System32\SET169.tmp deleted successfully.
C:\WINDOWS\System32\SET16A.tmp deleted successfully.
C:\WINDOWS\System32\SET16B.tmp deleted successfully.
C:\WINDOWS\System32\SET16C.tmp deleted successfully.
C:\WINDOWS\System32\SET16D.tmp deleted successfully.
C:\WINDOWS\System32\SET19A.tmp deleted successfully.
C:\WINDOWS\System32\SET19F.tmp deleted successfully.
C:\WINDOWS\System32\SET216.tmp deleted successfully.
C:\WINDOWS\System32\SET4DF.tmp deleted successfully.
C:\WINDOWS\System32\SET4E0.tmp deleted successfully.
C:\WINDOWS\System32\SET4E1.tmp deleted successfully.
C:\WINDOWS\System32\SET4E5.tmp deleted successfully.
C:\WINDOWS\System32\SET4E6.tmp deleted successfully.
C:\WINDOWS\System32\SET4E7.tmp deleted successfully.
C:\WINDOWS\System32\SET4EB.tmp deleted successfully.
C:\WINDOWS\System32\SET4EC.tmp deleted successfully.
C:\WINDOWS\System32\SET4ED.tmp deleted successfully.
C:\WINDOWS\System32\SETBA.tmp deleted successfully.
C:\WINDOWS\System32\SETBB.tmp deleted successfully.
C:\WINDOWS\System32\SETC0.tmp deleted successfully.
C:\WINDOWS\System32\SETC1.tmp deleted successfully.
C:\WINDOWS\System32\SETC6.tmp deleted successfully.
C:\WINDOWS\System32\SETCD.tmp deleted successfully.
C:\WINDOWS\System32\SETE4.tmp deleted successfully.
C:\WINDOWS\System32\SETEB.tmp deleted successfully.
C:\WINDOWS\System32\SETF3.tmp deleted successfully.
C:\WINDOWS\System32\SETF4.tmp deleted successfully.
C:\WINDOWS\System32\SETFB.tmp deleted successfully.
C:\WINDOWS\System32\SETFC.tmp deleted successfully.
C:\WINDOWS\003127_.tmp deleted successfully.
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job moved successfully.
File C:\WINDOWS\System32\drivers\uti3otqy.sys not found.
C:\Documents and Settings\All Users\Application Data\espionServerData folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Lavasoft\License folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Lavasoft folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\{D73C56FB-C526-4663-AC78-35A45DD3C6A9} folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\{6D268417-9C89-48B2-A1B0-C887FADC4E41} folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Symantec folder moved successfully.
Folder C:\Documents and Settings\muchacha\Application Data\BabylonToolbar\ not found.
Folder C:\Documents and Settings\muchacha\Application Data\Search Settings\ not found.
========== FILES ==========
File\Folder C:\Program Files\Search Settings not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrateur
->Temp folder emptied: 601 bytes
->Temporary Internet Files folder emptied: 150559 bytes
->FireFox cache emptied: 3387926 bytes
 
User: All Users
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49286 bytes
 
User: LocalService
->Temp folder emptied: 115616 bytes
->Temporary Internet Files folder emptied: 339564 bytes
 
User: muchacha
->Temp folder emptied: 3233517 bytes
->Temporary Internet Files folder emptied: 1782676 bytes
->Java cache emptied: 463 bytes
->FireFox cache emptied: 45688606 bytes
->Google Chrome cache emptied: 8741509 bytes
->Flash cache emptied: 4315429 bytes
 
User: NetworkService
->Temp folder emptied: 125878 bytes
->Temporary Internet Files folder emptied: 3095440 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 253686 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 786914001 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 818,00 mb
 
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.69.0 log created on 10252012_181603

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
Titre: Re : PC Espionné ?
Posté par: hyunkel30 le octobre 25, 2012, 19:25:15
Re,

Pour les rapports, pense à utiliser la page d'hébergement que tu avais utilisé en premier pour OTL ;)

Il me manque le rapport d'adwcleaner

Concernant Kaspersky, si c'est bien celui que tu veux supprimer (et donc garder Microsoft Security Essentials), voici un outil pour le supprimer :
http://www.inforumatique.fr/index.php/utilitaires/nettoyeurs-et-desinstallateurs/item/108-d%C3%A9sinstallateur-kaspersky.html

 :AAN